Recording apparatus, reproducing apparatus, and computer program product for recording and reproducing
Abstract
A recording apparatus stores first secret information uniquely allocated to the recording apparatus, reads media identification information for specifically identifying a recordable medium and encrypted disk key information encrypted by master key information from the recordable medium, and transmits these pieces of information to an authentication server. The recording apparatus receives an encrypted content encrypted by title key information and encrypted title key information from the authentication server. Further, the recording apparatus receives first certificate information for certifying that the authentication server permits recording of the content on the recordable medium from the authentication server, generates second certificate information by using the first certificate information and first secret information, and records the encrypted content, the encrypted title key information, and the second certificate information on the recordable medium.
Claims
exact text as granted — not AI-modified1 . A recording apparatus connected to an authentication server that permits recording of a content via a network, to record an encrypted content on a recordable medium, comprising:
a storage unit that stores first secret information uniquely allocated to the recording apparatus; a reading unit that reads media identification information for specifically identifying the recordable medium, and encrypted disk key information which is disk key information encrypted by master key information, from the recordable medium; a transmitting unit that transmits the media identification information and the encrypted disk key information to the authentication server; a first receiving unit that receives the encrypted content which is a content encrypted by title key information uniquely allocated to each content, and encrypted title key information which is the title key information encrypted by the disk key information, from the authentication server; a second receiving unit that receives first certificate information for certifying that the authentication server permits recording of the content on the recordable medium, which is generated by using at least the media identification information, from the authentication server; a generating unit that generates second certificate information by using the first certificate information and the first secret information; and a recording unit that records the encrypted content, the encrypted title key information, and the second certificate information on the recordable medium.
2 . The apparatus according to claim 1 , wherein the second receiving unit receives the first certificate information generated by using the media identification information, a second secret information uniquely allocated to the authentication server, and a content identification information from the authentication server.
3 . The apparatus according to claim 2 , wherein the second receiving unit receives a hash value calculated from the title key information used for encrypting the content, as the content identification information.
4 . The apparatus according to claim 1 , wherein the storage unit further stores first public key certificate information specifically corresponding to the first secret information, and
the recording unit further records the first public key certificate information on the recordable medium.
5 . The apparatus according to claim 1 , wherein the second receiving unit further receives management-organization certificate information, which is capable of specifically identifying the content and has a digital signature issued in advance by a management-organization added thereto, and
the recording unit further records the management-organization certificate information on the recordable medium.
6 . The apparatus according to claim 5 , wherein the second receiving unit receives the management-organization certificate information added with the digital signature issued in advance by the management-organization and including a hash value of the encrypted content.
7 . The apparatus according to claim 1 , wherein the first receiving unit receives the encrypted content in which the content having a digital watermark embedded therein is encrypted by the title key information, and the encrypted title key information from the authentication server.
8 . The apparatus according to claim 1 , wherein the recording unit records the encrypted content, the encrypted title key information, and the second certificate information on the recordable medium, on which discrimination information for discriminating a recordable medium having at least the media identification information and the second certificate information recorded thereon at the time of recording the encrypted content permitted by the authentication server, from a recordable medium on which the media identification information and the second certificate information are not recorded at the time of recording the encrypted content permitted by the authentication server is prerecorded unrewritably.
9 . A reproducing apparatus that reproduces a content encrypted and recorded on a recordable medium, comprising:
a storage unit that stores master key information; a read unit that reads encrypted disk key information which is disk key information encrypted by the master key information, an encrypted content which is a content encrypted by title key information uniquely allocated to each content, and encrypted title key information which is the title key information encrypted by the disk key information, from the recordable medium; a decrypting unit that decrypts the encrypted disk key information by using the master key information, and decrypts the encrypted title key information by using the decrypted disk key information, thereby obtaining the title key information; a verifying unit that verifies whether recording of the encrypted content on the recordable medium is permitted by an authentication server, by using at least media identification information capable of specifically identifying the recordable medium, and second certificate information generated by a recording apparatus by using first certificate information, which is generated by using at least the media identification information, for certifying that the authentication server permits recording of the content on the recordable medium, and first secret information uniquely allocated to the recording apparatus, when the media identification information and the second certificate information are recorded on the recordable medium; and a reproducing unit that decrypts the encrypted content by using the title key information to reproduce the content, when it is verified that recording of the encrypted content on the recordable medium is permitted by the authentication server.
10 . The apparatus according to claim 9 , wherein the verifying unit verifies whether recording of the encrypted content on the recordable medium is permitted by the authentication server by using the media identification information, the second certificate information, and the first public key certificate information specifically corresponding to the first secret information, when the media identification information, the second certificate information, and the first public key certificate information are further recorded on the recordable medium.
11 . The apparatus according to claim 10 , wherein
the storage unit stores management-organization public key information specifically corresponding to management-organization certificate information added with a digital signature issued in advance by a management-organization and capable of specifically identifying the content, and when the media identification information, the second certificate information, the first public key certificate information, and the management-organization certificate information are further recorded on the recordable medium, the verifying unit verifies the management-organization certificate information by using the management-organization public key information, and according to a verification result thereof, verifies the first public key certificate information by using the management-organization public key information, and according to a verification result thereof, verifies whether recording of the encrypted content on the recordable medium is permitted by the authentication server, by using the media identification information, the second certificate information, and the first public key certificate information.
12 . The apparatus according to claim 10 , wherein the management-organization certificate information includes a hash value calculated from the encrypted content,
the apparatus further comprises a first calculating unit that calculates a hash value of the encrypted content recorded on the recordable medium is further included, and the verifying unit compares the calculated hash value of the encrypted content with the hash value included in the management-organization certificate information recorded on the recordable medium, and when these hash values match each other, verifies the management-organization certificate information by using the management-organization public key information.
13 . The apparatus according to claim 10 , wherein the second certificate information is generated by using the first certificate information generated by using the media identification information, the second secret information uniquely allocated to the authentication server, and the hash value calculated from the title key information used for encryption of the content, and the first secret information,
the apparatus further comprises a second calculating unit that calculates a hash value of the obtained disk key information is further included, and the verifying unit verifies whether recording of the encrypted content on the recordable medium is permitted by the authentication server, by using the media identification information, the second certificate information, the first public key certificate information, and the hash value of the disk key information.
14 . The apparatus according to claim 9 , wherein when it is verified that recording of the encrypted content on the recordable medium is not permitted by the authentication server, the reproducing unit does not reproduce the content.
15 . The apparatus according to claim 9 , wherein when at least the media identification information and the second certificate information are not recorded on the recordable medium, the reproducing unit decrypts the encrypted content by using the obtained title key information, to obtain and reproduce the content.
16 . The apparatus according to claim 9 , wherein the recordable medium further records discrimination information for discriminating a recordable medium having at least the media identification information and the second certificate information recorded thereon at the time of recording the encrypted content permitted by the authentication server, from a recordable medium on which the media identification information and the second certificate information are not recorded at the time of recording the encrypted content permitted by the authentication server,
the apparatus further comprises a detecting unit that detects the discrimination information recorded on the recordable medium is further included, and when the discrimination information is detected, and when the media identification information and the second certificate information are not recorded on the recordable medium, the reproducing unit does not reproduce the content.
17 . The apparatus according to claim 16 , wherein when the discrimination information is not detected, the reproducing unit decrypts the encrypted content by using the obtained title key information, to obtain and reproduce the content.
18 . A reproducing apparatus that reproduces a content encrypted and recorded on a recordable medium, comprising:
a storage unit that stores master key information; a read unit that reads encrypted disk key information, which is disk key information encrypted by the master key information, an encrypted content, which is a content having a digital watermark embedded therein for indicating that an authentication server that permits recording of contents permits recording of the content on the recordable medium and encrypted by title key information uniquely allocated to each content, and encrypted title key information, which is the title key information encrypted by the disk key information, from the recordable medium; a decrypting unit that decrypts the encrypted disk key information by using the master key information, and decrypts the encrypted title key information by using the decrypted disk key information, to thereby obtain the title key information; a reproducing unit that decrypts the encrypted content by using the title key information, to reproduce the content; a detecting unit that detects the appropriate digital watermark from the content to be reproduced; and a verifying unit that verifies whether recording of the encrypted content on the recordable medium is permitted by the authentication server, by using at least media identification information capable of specifically identifying the recordable medium, and second certificate information generated by a recording apparatus by using first certificate information, which is generated by using at least the media identification information, for certifying that the authentication server permits recording of the content on the recordable medium, and first secret information uniquely allocated to the recording apparatus, when the appropriate digital watermark is detected and the media identification information and the second certificate information are recorded on the recordable medium, wherein when the appropriate digital watermark is detected and the media identification information and the second certificate information are not recorded on the recordable medium, or when it is verified that recording of the encrypted content is not permitted by the authentication server, the reproducing unit aborts reproduction of the content.
19 . The apparatus according to claim 18 , wherein when the appropriate digital watermark is not detected or when it is verified that recording of the encrypted content is permitted by the authentication server, the reproducing unit continues reproduction of the content.
20 . A computer program product having a computer readable medium including programmed instructions, when executed by a computer provided in a recording apparatus connected to an authentication server that permits recording of a content via a network, to record an encrypted content on a recordable medium, and includes a storage unit that stores first secret information uniquely allocated to the recording apparatus, wherein the instructions, cause the computer to perform:
reading media identification information for specifically identifying the recordable medium, and encrypted disk key information which is disk key information encrypted by master key information, from the recordable medium; transmitting the media identification information and the encrypted disk key information to the authentication server; receiving the encrypted content which is a content encrypted by title key information uniquely allocated to each content, and encrypted title key information which is the title key information encrypted by the disk key information, from the authentication server; receiving first certificate information for certifying that the authentication server permits recording of the content on the recordable medium, which is generated by using at least the media identification information, from the authentication server; generating second certificate information by using the first certificate information and the first secret information; and recording the encrypted content, the encrypted title key information, and the second certificate information on the recordable medium.
21 . A computer program product having a computer readable medium including programmed instructions, when executed by a computer provided in a reproducing apparatus that reproduces a content encrypted by title key information uniquely allocated to each content and recorded on a recordable medium, and includes a storage unit that stores master key information, wherein the instructions, cause the computer to perform:
reading encrypted disk key information which is disk key information encrypted by the master key information, and encrypted title key information which is the title key information encrypted by the disk key information, from the recordable medium; obtaining the title key information by decrypting the encrypted disk key information by using the master key information and decrypting the encrypted title key information by using the decrypted disk key information; verifying whether recording of the encrypted content on the recordable medium is permitted by an authentication server, by using at least media identification information capable of specifically identifying the recordable medium, and second certificate information generated by a recording apparatus by using first certificate information, which is generated by using at least the media identification information, for certifying that the authentication server permits recording of the content on the recordable medium, and first secret information uniquely allocated to the recording apparatus, when the media identification information and the second certificate information are recorded on the recordable medium; reading the content from the recordable medium, when it is verified that recording of the content on the recordable medium is permitted by the authentication server; and decrypting the read content by using the obtained title key information to reproduce the content.Join the waitlist — get patent alerts
Track US2009202071A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.